« Volver al listado

CVE-2017-1001002

Estado: ModificadaCrítica (9.8)—

math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-1001002",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "46fe6300-5254-4a98-9594-a9567bec8179",
      "affectedData": [
        {
          "vendor": "math.js",
          "product": "math.js",
          "versions": [
            {
              "status": "affected",
              "version": "3.17.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-11-27T14:29:00.240",
  "references": [
    {
      "url": "https://github.com/josdejong/mathjs/blob/master/HISTORY.md#2017-11-18-version-3170",
      "source": "46fe6300-5254-4a98-9594-a9567bec8179"
    },
    {
      "url": "https://github.com/josdejong/mathjs/commit/8d2d48d81b3c233fb64eb2ec1d7a9e1cf6a55a90",
      "source": "46fe6300-5254-4a98-9594-a9567bec8179"
    },
    {
      "url": "https://github.com/josdejong/mathjs/blob/master/HISTORY.md#2017-11-18-version-3170",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/josdejong/mathjs/commit/8d2d48d81b3c233fb64eb2ec1d7a9e1cf6a55a90",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "46fe6300-5254-4a98-9594-a9567bec8179",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution."
    },
    {
      "lang": "es",
      "value": "Las versiones anteriores a la 3.17.0 de math.js tenían una vulnerabilidad de ejecución de código arbitrario en el motor de JavaScript. La creación de una función escrita con código JavaScript en el nombre podría resultar en la ejecución arbitraria."
    }
  ],
  "lastModified": "2026-06-17T00:59:18.840",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mathjs:math.js:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CAA4C359-CEFC-48E5-ADD9-42689961238F",
              "versionEndIncluding": "3.17.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "46fe6300-5254-4a98-9594-a9567bec8179"
}